Skip to content

Commit a307d45

Browse files
github-actions[bot]web-flow
authored andcommitted
chore: update SBOM for Python 3.9 (intel#3502)
Co-authored-by: GitHub <[email protected]>
1 parent 685fdf1 commit a307d45

File tree

2 files changed

+52
-52
lines changed

2 files changed

+52
-52
lines changed

sbom/cve-bin-tool-py3.9.json

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
"$schema": "http://cyclonedx.org/schema/bom-1.5.schema.json",
33
"bomFormat": "CycloneDX",
44
"specVersion": "1.5",
5-
"serialNumber": "urn:uuid:49e5ab23-133b-4db2-9fa2-6bb79a50ff57",
5+
"serialNumber": "urn:uuid:233d04b0-bdbb-4457-bac7-f220a1ddaf27",
66
"version": 1,
77
"metadata": {
8-
"timestamp": "2023-10-30T00:26:16Z",
8+
"timestamp": "2023-11-06T00:25:57Z",
99
"tools": {
1010
"components": [
1111
{
@@ -218,7 +218,7 @@
218218
"type": "library",
219219
"bom-ref": "7-charset-normalizer",
220220
"name": "charset-normalizer",
221-
"version": "3.3.1",
221+
"version": "3.3.2",
222222
"supplier": {
223223
"name": "Ahmed TAHRI",
224224
"contact": [
@@ -227,7 +227,7 @@
227227
}
228228
]
229229
},
230-
"cpe": "cpe:2.3:a:ahmed_tahri:charset-normalizer:3.3.1:*:*:*:*:*:*:*",
230+
"cpe": "cpe:2.3:a:ahmed_tahri:charset-normalizer:3.3.2:*:*:*:*:*:*:*",
231231
"description": "The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.",
232232
"licenses": [
233233
{
@@ -239,12 +239,12 @@
239239
],
240240
"externalReferences": [
241241
{
242-
"url": "https://pypi.org/project/charset-normalizer/3.3.1",
242+
"url": "https://pypi.org/project/charset-normalizer/3.3.2",
243243
"type": "distribution",
244244
"comment": "Download location for component"
245245
}
246246
],
247-
"purl": "pkg:pypi/[email protected].1"
247+
"purl": "pkg:pypi/[email protected].2"
248248
},
249249
{
250250
"type": "library",
@@ -544,7 +544,7 @@
544544
"type": "library",
545545
"bom-ref": "17-argcomplete",
546546
"name": "argcomplete",
547-
"version": "3.1.2",
547+
"version": "3.1.4",
548548
"supplier": {
549549
"name": "Andrey Kislyuk",
550550
"contact": [
@@ -553,7 +553,7 @@
553553
}
554554
]
555555
},
556-
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.2:*:*:*:*:*:*:*",
556+
"cpe": "cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.4:*:*:*:*:*:*:*",
557557
"description": "Bash tab completion for argparse",
558558
"licenses": [
559559
{
@@ -565,12 +565,12 @@
565565
],
566566
"externalReferences": [
567567
{
568-
"url": "https://pypi.org/project/argcomplete/3.1.2",
568+
"url": "https://pypi.org/project/argcomplete/3.1.4",
569569
"type": "distribution",
570570
"comment": "Download location for component"
571571
}
572572
],
573-
"purl": "pkg:pypi/[email protected].2",
573+
"purl": "pkg:pypi/[email protected].4",
574574
"properties": [
575575
{
576576
"name": "License Comments",
@@ -1228,7 +1228,7 @@
12281228
"type": "library",
12291229
"bom-ref": "37-google-auth",
12301230
"name": "google-auth",
1231-
"version": "2.23.3",
1231+
"version": "2.23.4",
12321232
"supplier": {
12331233
"name": "Google Cloud Platform",
12341234
"contact": [
@@ -1237,7 +1237,7 @@
12371237
}
12381238
]
12391239
},
1240-
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.23.3:*:*:*:*:*:*:*",
1240+
"cpe": "cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*",
12411241
"description": "Google Authentication Library",
12421242
"licenses": [
12431243
{
@@ -1249,12 +1249,12 @@
12491249
],
12501250
"externalReferences": [
12511251
{
1252-
"url": "https://pypi.org/project/google-auth/2.23.3",
1252+
"url": "https://pypi.org/project/google-auth/2.23.4",
12531253
"type": "distribution",
12541254
"comment": "Download location for component"
12551255
}
12561256
],
1257-
"purl": "pkg:pypi/[email protected].3",
1257+
"purl": "pkg:pypi/[email protected].4",
12581258
"properties": [
12591259
{
12601260
"name": "License Comments",
@@ -1443,11 +1443,11 @@
14431443
"type": "library",
14441444
"bom-ref": "44-jsonschema",
14451445
"name": "jsonschema",
1446-
"version": "4.19.1",
1446+
"version": "4.19.2",
14471447
"supplier": {
14481448
"name": "Julian Berman"
14491449
},
1450-
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.19.1:*:*:*:*:*:*:*",
1450+
"cpe": "cpe:2.3:a:julian_berman:jsonschema:4.19.2:*:*:*:*:*:*:*",
14511451
"description": "An implementation of JSON Schema validation for Python",
14521452
"licenses": [
14531453
{
@@ -1459,12 +1459,12 @@
14591459
],
14601460
"externalReferences": [
14611461
{
1462-
"url": "https://pypi.org/project/jsonschema/4.19.1",
1462+
"url": "https://pypi.org/project/jsonschema/4.19.2",
14631463
"type": "distribution",
14641464
"comment": "Download location for component"
14651465
}
14661466
],
1467-
"purl": "pkg:pypi/[email protected].1"
1467+
"purl": "pkg:pypi/[email protected].2"
14681468
},
14691469
{
14701470
"type": "library",
@@ -1524,11 +1524,11 @@
15241524
"type": "library",
15251525
"bom-ref": "47-rpds-py",
15261526
"name": "rpds-py",
1527-
"version": "0.10.6",
1527+
"version": "0.12.0",
15281528
"supplier": {
15291529
"name": "Julian Berman"
15301530
},
1531-
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.10.6:*:*:*:*:*:*:*",
1531+
"cpe": "cpe:2.3:a:julian_berman:rpds-py:0.12.0:*:*:*:*:*:*:*",
15321532
"description": "Python bindings to Rust's persistent data structures (rpds)",
15331533
"licenses": [
15341534
{
@@ -1540,12 +1540,12 @@
15401540
],
15411541
"externalReferences": [
15421542
{
1543-
"url": "https://pypi.org/project/rpds-py/0.10.6",
1543+
"url": "https://pypi.org/project/rpds-py/0.12.0",
15441544
"type": "distribution",
15451545
"comment": "Download location for component"
15461546
}
15471547
],
1548-
"purl": "pkg:pypi/rpds-py@0.10.6"
1548+
"purl": "pkg:pypi/rpds-py@0.12.0"
15491549
},
15501550
{
15511551
"type": "library",
@@ -2157,7 +2157,7 @@
21572157
"type": "library",
21582158
"bom-ref": "67-zstandard",
21592159
"name": "zstandard",
2160-
"version": "0.21.0",
2160+
"version": "0.22.0",
21612161
"supplier": {
21622162
"name": "Gregory Szorc",
21632163
"contact": [
@@ -2166,7 +2166,7 @@
21662166
}
21672167
]
21682168
},
2169-
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.21.0:*:*:*:*:*:*:*",
2169+
"cpe": "cpe:2.3:a:gregory_szorc:zstandard:0.22.0:*:*:*:*:*:*:*",
21702170
"description": "Zstandard bindings for Python",
21712171
"licenses": [
21722172
{
@@ -2178,12 +2178,12 @@
21782178
],
21792179
"externalReferences": [
21802180
{
2181-
"url": "https://pypi.org/project/zstandard/0.21.0",
2181+
"url": "https://pypi.org/project/zstandard/0.22.0",
21822182
"type": "distribution",
21832183
"comment": "Download location for component"
21842184
}
21852185
],
2186-
"purl": "pkg:pypi/zstandard@0.21.0",
2186+
"purl": "pkg:pypi/zstandard@0.22.0",
21872187
"properties": [
21882188
{
21892189
"name": "License Comments",

sbom/cve-bin-tool-py3.9.spdx

Lines changed: 26 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@ SPDXVersion: SPDX-2.3
22
DataLicense: CC0-1.0
33
SPDXID: SPDXRef-DOCUMENT
44
DocumentName: Python-cve-bin-tool
5-
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-156d1333-107b-45f2-9bab-245ab3e876cb
5+
DocumentNamespace: http://spdx.org/spdxdocs/Python-cve-bin-tool-f6fb3e58-b97b-457f-b808-a1adf2ef6fc6
66
LicenseListVersion: 3.21
77
Creator: Tool: sbom4python-0.10.0
8-
Created: 2023-10-30T00:24:47Z
8+
Created: 2023-11-06T00:24:49Z
99
CreatorComment: <text>This document has been automatically generated.</text>
1010
#####
1111

@@ -101,17 +101,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:hynek_schlawack:attrs:23.1.0:*:*:*:*:*
101101

102102
PackageName: charset-normalizer
103103
SPDXID: SPDXRef-Package-7-charset-normalizer
104-
PackageVersion: 3.3.1
104+
PackageVersion: 3.3.2
105105
PrimaryPackagePurpose: LIBRARY
106106
PackageSupplier: Person: Ahmed TAHRI ([email protected])
107-
PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.3.1
107+
PackageDownloadLocation: https://pypi.org/project/charset-normalizer/3.3.2
108108
FilesAnalyzed: false
109109
PackageLicenseDeclared: MIT
110110
PackageLicenseConcluded: MIT
111111
PackageCopyrightText: NOASSERTION
112112
PackageSummary: <text>The Real First Universal Charset Detector. Open, modern and actively maintained alternative to Chardet.</text>
113-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
114-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_tahri:charset-normalizer:3.3.1:*:*:*:*:*:*:*
113+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
114+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:ahmed_tahri:charset-normalizer:3.3.2:*:*:*:*:*:*:*
115115
#####
116116

117117
PackageName: multidict
@@ -256,18 +256,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_inc.:gsutil:5.27:*:*:*:*:*:*:*
256256

257257
PackageName: argcomplete
258258
SPDXID: SPDXRef-Package-17-argcomplete
259-
PackageVersion: 3.1.2
259+
PackageVersion: 3.1.4
260260
PrimaryPackagePurpose: LIBRARY
261261
PackageSupplier: Person: Andrey Kislyuk ([email protected])
262-
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.1.2
262+
PackageDownloadLocation: https://pypi.org/project/argcomplete/3.1.4
263263
FilesAnalyzed: false
264264
PackageLicenseDeclared: NOASSERTION
265265
PackageLicenseConcluded: Apache-2.0
266266
PackageLicenseComments: <text>argcomplete declares Apache Software License which is not currently a valid SPDX License identifier or expression.</text>
267267
PackageCopyrightText: NOASSERTION
268268
PackageSummary: <text>Bash tab completion for argparse</text>
269-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
270-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.2:*:*:*:*:*:*:*
269+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
270+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:andrey_kislyuk:argcomplete:3.1.4:*:*:*:*:*:*:*
271271
#####
272272

273273
PackageName: crcmod
@@ -566,18 +566,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:craig_citro:google-apitools:0.5.32:*:*
566566

567567
PackageName: google-auth
568568
SPDXID: SPDXRef-Package-37-google-auth
569-
PackageVersion: 2.23.3
569+
PackageVersion: 2.23.4
570570
PrimaryPackagePurpose: LIBRARY
571571
PackageSupplier: Organization: Google Cloud Platform ([email protected])
572-
PackageDownloadLocation: https://pypi.org/project/google-auth/2.23.3
572+
PackageDownloadLocation: https://pypi.org/project/google-auth/2.23.4
573573
FilesAnalyzed: false
574574
PackageLicenseDeclared: NOASSERTION
575575
PackageLicenseConcluded: Apache-2.0
576576
PackageLicenseComments: <text>google-auth declares Apache 2.0 which is not currently a valid SPDX License identifier or expression.</text>
577577
PackageCopyrightText: NOASSERTION
578578
PackageSummary: <text>Google Authentication Library</text>
579-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].3
580-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.23.3:*:*:*:*:*:*:*
579+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].4
580+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:google_cloud_platform:google-auth:2.23.4:*:*:*:*:*:*:*
581581
#####
582582

583583
PackageName: cachetools
@@ -672,17 +672,17 @@ ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected]
672672

673673
PackageName: jsonschema
674674
SPDXID: SPDXRef-Package-44-jsonschema
675-
PackageVersion: 4.19.1
675+
PackageVersion: 4.19.2
676676
PrimaryPackagePurpose: LIBRARY
677677
PackageSupplier: Person: Julian Berman
678-
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.19.1
678+
PackageDownloadLocation: https://pypi.org/project/jsonschema/4.19.2
679679
FilesAnalyzed: false
680680
PackageLicenseDeclared: MIT
681681
PackageLicenseConcluded: MIT
682682
PackageCopyrightText: NOASSERTION
683683
PackageSummary: <text>An implementation of JSON Schema validation for Python</text>
684-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].1
685-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.19.1:*:*:*:*:*:*:*
684+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/[email protected].2
685+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:jsonschema:4.19.2:*:*:*:*:*:*:*
686686
#####
687687

688688
PackageName: jsonschema-specifications
@@ -717,17 +717,17 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:referencing:0.30.2:*:*:*
717717

718718
PackageName: rpds-py
719719
SPDXID: SPDXRef-Package-47-rpds-py
720-
PackageVersion: 0.10.6
720+
PackageVersion: 0.12.0
721721
PrimaryPackagePurpose: LIBRARY
722722
PackageSupplier: Person: Julian Berman
723-
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.10.6
723+
PackageDownloadLocation: https://pypi.org/project/rpds-py/0.12.0
724724
FilesAnalyzed: false
725725
PackageLicenseDeclared: MIT
726726
PackageLicenseConcluded: MIT
727727
PackageCopyrightText: NOASSERTION
728728
PackageSummary: <text>Python bindings to Rust's persistent data structures (rpds)</text>
729-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.10.6
730-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.10.6:*:*:*:*:*:*:*
729+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/rpds-py@0.12.0
730+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:julian_berman:rpds-py:0.12.0:*:*:*:*:*:*:*
731731
#####
732732

733733
PackageName: lib4sbom
@@ -1022,18 +1022,18 @@ ExternalRef: SECURITY cpe23Type cpe:2.3:a:davide_brunato:elementpath:4.1.5:*:*:*
10221022

10231023
PackageName: zstandard
10241024
SPDXID: SPDXRef-Package-67-zstandard
1025-
PackageVersion: 0.21.0
1025+
PackageVersion: 0.22.0
10261026
PrimaryPackagePurpose: LIBRARY
10271027
PackageSupplier: Person: Gregory Szorc ([email protected])
1028-
PackageDownloadLocation: https://pypi.org/project/zstandard/0.21.0
1028+
PackageDownloadLocation: https://pypi.org/project/zstandard/0.22.0
10291029
FilesAnalyzed: false
10301030
PackageLicenseDeclared: NOASSERTION
10311031
PackageLicenseConcluded: BSD-3-Clause
10321032
PackageLicenseComments: <text>zstandard declares BSD which is not currently a valid SPDX License identifier or expression.</text>
10331033
PackageCopyrightText: NOASSERTION
10341034
PackageSummary: <text>Zstandard bindings for Python</text>
1035-
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/zstandard@0.21.0
1036-
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.21.0:*:*:*:*:*:*:*
1035+
ExternalRef: PACKAGE-MANAGER purl pkg:pypi/zstandard@0.22.0
1036+
ExternalRef: SECURITY cpe23Type cpe:2.3:a:gregory_szorc:zstandard:0.22.0:*:*:*:*:*:*:*
10371037
#####
10381038

10391039
Relationship: SPDXRef-Package-1-cve-bin-tool DEPENDS_ON SPDXRef-Package-11-beautifulsoup4

0 commit comments

Comments
 (0)